Personal data · experimental processing
Privacy Policy
Last updated 16 September 2026 · Effective immediately · Experimental system
This Privacy Policy explains what information Primacy Vault processes, why, how long, with whom it is shared, and the choices you have. It is written for a global audience and is intended to satisfy transparency duties under the EU/UK GDPR, the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and similar laws, without claiming that Primacy is established in every jurisdiction or that a Data Protection Officer has been appointed. If a conflict exists between this Policy and a non-waivable statute that applies to you, that statute controls.
1. Controller, processors, and experimental status
Until a formed entity is named in a later notice, the operator of the Platform is the controller of personal data processed to run your account. xAI is a processor / sub-processor when you invoke SuperGrok. Hosting, analytics (if enabled), and any future SMTP/Resend provider are processors for their respective functions. Circle, public blockchains, and your own email provider are independent controllers of data you send to them.
This environment may store account, palace, wallet-link, outreach, and mail-outbox data locally to the session (for example in browser storage) until a production backend you approve is connected. Local storage is still personal data if it identifies you.
2. Categories of personal data
Account data: email, password verifier or equivalent, display name, selected plan, industry, timestamps.
Vault and palace data: rooms, entries, triples, tunnels, AAAK summaries, SuperGrok briefs and outputs you generate. This may include sensitive professional opinions. Do not put health, children’s, or government-ID data in the palace unless you have a lawful basis and accept the experimental risk.
Wallet data: public addresses you link, active-address selection, stake and royalty ledger entries. We do not ask for seed phrases. Never paste a seed phrase into SuperGrok or a support form.
Outreach data: campaign metadata, buyer company names you type, buyer emails you type, letter subject/body, Auditor verdicts, job amounts, send/reply timestamps you log.
Mail data: transactional messages queued or sent to YOUR email (letter ready, job activation, receipts), delivery status if a provider returns it.
Technical data: device/browser type, approximate timestamps, error logs, and security events. We do not need your precise GPS location.
We do not intentionally collect data from children under 16 (13 in the U.S. where COPPA applies). If we learn we have, we will delete it.
3. Purposes and legal bases (GDPR-style)
Perform the contract / requested service: account, vault, outreach OS, royalty ledger, transactional mail to you (Art. 6(1)(b) GDPR where it applies).
Legitimate interests: security, abuse detection, anti-hallucination scanning, product improvement of prompts, defending legal claims (Art. 6(1)(f)), balanced against your rights. You may object where that law applies.
Consent: optional cookies beyond strictly necessary; marketing mail if we ever send it (we do not as of this date). Withdrawal does not affect prior processing.
Legal obligation: tax, sanctions screening, or lawful process if and when a production operator is subject to those duties.
5. Retention
Account and vault: for the life of the account plus a short wind-down, unless you delete.
Outreach and mail outbox: for the life of the account so you can prove what you logged; you may delete campaigns in-product where that control exists.
SuperGrok logs: short operational retention in-product; xAI retains according to its own policy.
Legal hold: we may retain a copy if we reasonably anticipate a dispute.
When the production backend arrives, retention schedules will be republished. Until then, clearing browser storage may destroy your only copy. Export anything you cannot afford to lose.
6. International transfers
xAI and many hosts process in the United States. If you are in the EEA/UK/Switzerland, this is a third-country transfer. Standard Contractual Clauses or successor mechanisms will be put in place with processors when the production backend is contracted. Until then, experimental use is at your risk. You may choose not to invoke SuperGrok.
7. Your rights
Depending on law, you may have rights to access, correct, delete, port, restrict, or object to processing, and to withdraw consent. CCPA/CPRA: rights to know, delete, correct, and opt out of sale/share (we do not sell/share as of this date), and not to be discriminated against for exercising rights. We will not honor a request we cannot authenticate.
Submit requests via the contact method in the FAQ. We will respond within the statutory period (typically 30–45 days) once a production identity-verification path exists. In this experimental environment, deleting your account data in-product / clearing storage is the practical deletion path.
EEA/UK users may complain to a supervisory authority. U.S. users may contact a state attorney general. This does not waive our position that the Platform is experimental.
8. Security
We apply best-effort technical and organizational measures appropriate to an experimental app: transport encryption in production hosting, access minimization, anti-hallucination scanning, and wallet-connect gating for money actions. No method is 100% secure. You must use a unique password, protect keys, and treat SuperGrok output as untrusted.
SOC 2: we are not certified. See the Trust page for the control mapping we operate toward.
10. Changes
We will post updates with a new date. Material changes that expand processing in a way that requires consent will be put behind a consent step where law requires it.
This Policy is interpreted under the laws of the State of Wyoming, United States, consistent with the Terms of Service. Exclusive venue is Laramie County, Wyoming, except where a non-waivable statute requires otherwise.
These documents are not a substitute for independent legal, tax, or investment advice. Primacy Vault is experimental. User beware.